Connecting Meta the safe way: a read-only System User token
Most tools ask for a Meta login or a token with management permissions. That means a leaked token could pause campaigns, drain budgets, or remove people from your Business Manager. We think that’s an unacceptable trade for a reporting tool — so ROASTED is built around a read-only System User token.
Why a System User
A System User is a non-human identity inside your Business Manager. It has three properties that matter here:
- Its token never expires — no 60-day re-login dance.
- It only sees the ad accounts you explicitly assign to it.
- With assets assigned as View performance, the platform itself rejects every write — renaming, budget changes, member removal, all of it.
We don’t take Meta’s word for that last point. We ran the full battery against our own token: eleven different write attempts — edit campaign, remove a Business Manager member, create ad accounts, claim assets — and all eleven were rejected by Meta. Numbers in, nothing out.
Setup in four steps
- In Business settings → Users → System users, create a system user with Employee access (not Admin).
- Assign the ad accounts you want reported, each as View performance only.
- Generate a token for your app with the
ads_readpermission. - Paste the token into the Meta Ads card in Connect accounts. Done.
If someone ever stole that token, they could read charts. That’s the whole blast radius — and that’s the point.